Wireless Based Attacks 


Objectives 


e Explain how wireless networks work 
e Discuss threats against wireless networks 


e Understand how to protect yourself when on an 
untrusted wireless network 


Wireless is everywhere! 


e Some organizations don’t even put wired ports in 
anymore 


e Nearly all devices out there come with some kind of 
wireless connection 


e We get frustrated if we don’t have signal 


How wireless works 


e What do we need to know? 
e Channels - 20Ghz, 40Ghz, 80Ghz 
e Lower the frequency, lower the speed 
e Base station serves an SSID 
e Client connects to an SSID (Service Set Identifier) 
e SSID can be really most anything! 


Threats to clients 


e Connecting to a spoofed SSID 
e Attacker/owner can sniff traffic 


e Connecting to unsecured SSID (open) 
e Attacker could perform a man in the middle attack 
e Denial of service - sending disconnects 


Threats to infrastructure 


e Signal interference - too many APs or SSIDs 
e Spoofing SSIDs 

e WPS - Wifi protected setup 

e Usernames/passwords 

e Backdoors 


e What was protected through wires, now allows anyone 
to connect 


Threats to communications 


e SSID is secured with WEP (Wireless Equivalent Privacy) 
e Keys can be obtained within seconds 


¢Untrusted networks 
e Encryption is not built into Open SSIDs 


Defenses 


e Use trusted networks 
e Secure SSIDs using well known and secure protocols 


e Only broadcast where you intent to use the signal 
(physicality) 


